test(actions): add unit tests for twofactor authentication actions
This commit is contained in:
1 parent
f762db9ef9
commit
d5ea115d31
1 file changed
+208
@@ -0,0 +1,208 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
// Hoisted mocks
|
||||
const mockRedirect = vi.hoisted(() =>
|
||||
vi.fn((url: string) => {
|
||||
const err = new Error(`NEXT_REDIRECT: ${url}`);
|
||||
// biome-ignore lint/suspicious/noExplicitAny: Next.js redirect signature
|
||||
(err as any).digest = `NEXT_REDIRECT;replace;${url};307;;`;
|
||||
throw err;
|
||||
}),
|
||||
);
|
||||
vi.mock("next/navigation", () => ({
|
||||
redirect: mockRedirect,
|
||||
}));
|
||||
|
||||
const mockRevalidatePath = vi.hoisted(() => vi.fn());
|
||||
vi.mock("next/cache", () => ({
|
||||
revalidatePath: mockRevalidatePath,
|
||||
unstable_cache: (fn: unknown) => fn,
|
||||
}));
|
||||
|
||||
vi.mock("next/server", () => ({
|
||||
NextResponse: {
|
||||
json: vi.fn(),
|
||||
},
|
||||
}));
|
||||
|
||||
vi.mock("next-auth", () => ({
|
||||
default: vi.fn(() => ({
|
||||
handlers: {},
|
||||
auth: vi.fn(),
|
||||
signOut: vi.fn(),
|
||||
})),
|
||||
}));
|
||||
|
||||
const mockAuth = vi.hoisted(() => vi.fn());
|
||||
vi.mock("@/lib/auth", () => ({
|
||||
auth: mockAuth,
|
||||
handlers: {},
|
||||
signOut: vi.fn(),
|
||||
}));
|
||||
|
||||
const mockRateLimit = vi.hoisted(() => vi.fn());
|
||||
vi.mock("@/lib/rate-limit", () => ({
|
||||
rateLimit: mockRateLimit,
|
||||
}));
|
||||
|
||||
const mockVerifyTotp = vi.hoisted(() => vi.fn());
|
||||
const mockGenerateTotpSecret = vi.hoisted(() => vi.fn());
|
||||
vi.mock("@/lib/auth/totp", () => ({
|
||||
verifyTotp: mockVerifyTotp,
|
||||
generateTotpSecret: mockGenerateTotpSecret,
|
||||
}));
|
||||
|
||||
const mockEncrypt = vi.hoisted(() => vi.fn());
|
||||
const mockDecrypt = vi.hoisted(() => vi.fn());
|
||||
vi.mock("@/lib/auth/laravel-encrypter", () => ({
|
||||
LaravelEncrypter: class {
|
||||
encrypt = mockEncrypt;
|
||||
decrypt = mockDecrypt;
|
||||
},
|
||||
}));
|
||||
|
||||
vi.mock("@/env", () => ({
|
||||
env: {
|
||||
APP_KEY: "base64:dGVzdGtleXRlc3RrZXl0ZXN0a2V5dGVzdGtleTEyMw==",
|
||||
},
|
||||
}));
|
||||
|
||||
const hoistedInsertValues = vi.hoisted(() => vi.fn());
|
||||
const hoistedSelectLimit = vi.hoisted(() => vi.fn());
|
||||
const hoistedSelectWhere = vi.hoisted(() =>
|
||||
vi.fn(() => ({ limit: hoistedSelectLimit })),
|
||||
);
|
||||
const hoistedSelectFrom = vi.hoisted(() =>
|
||||
vi.fn(() => ({ where: hoistedSelectWhere })),
|
||||
);
|
||||
const hoistedUpdateWhere = vi.hoisted(() => vi.fn());
|
||||
const hoistedUpdateSet = vi.hoisted(() =>
|
||||
vi.fn(() => ({ where: hoistedUpdateWhere })),
|
||||
);
|
||||
|
||||
vi.mock("@/lib/db", () => ({
|
||||
db: {
|
||||
select: vi.fn(() => ({ from: hoistedSelectFrom })),
|
||||
insert: vi.fn(() => ({ values: hoistedInsertValues })),
|
||||
update: vi.fn(() => ({ set: hoistedUpdateSet })),
|
||||
},
|
||||
User: {
|
||||
id: "user.id",
|
||||
twoFactorSecret: "user.twoFactorSecret",
|
||||
twoFactorConfirmedAt: "user.twoFactorConfirmedAt",
|
||||
twoFactorRecoveryCodes: "user.twoFactorRecoveryCodes",
|
||||
},
|
||||
}));
|
||||
|
||||
import { db, User } from "@/lib/db";
|
||||
import {
|
||||
beginTwoFactor,
|
||||
confirmTwoFactor,
|
||||
disableTwoFactor,
|
||||
} from "./twofactor";
|
||||
|
||||
const fakeForm = (data: Record<string, string>) =>
|
||||
({
|
||||
get: (key: string) => data[key] ?? null,
|
||||
}) as unknown as FormData;
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
mockAuth.mockResolvedValue({ user: { id: "42" } });
|
||||
mockRateLimit.mockResolvedValue({ ok: true });
|
||||
mockGenerateTotpSecret.mockReturnValue("JBSWY3DPEHPK3PXP");
|
||||
mockEncrypt.mockReturnValue("encrypted-secret-payload");
|
||||
mockDecrypt.mockReturnValue("JBSWY3DPEHPK3PXP");
|
||||
hoistedUpdateWhere.mockResolvedValue([]);
|
||||
hoistedSelectLimit.mockResolvedValue([
|
||||
{
|
||||
twoFactorSecret: "encrypted-secret-payload",
|
||||
twoFactorRecoveryCodes: JSON.stringify(["CODE-1234", "CODE-5678"]),
|
||||
},
|
||||
]);
|
||||
});
|
||||
|
||||
describe("beginTwoFactor", () => {
|
||||
it("redirects to login if not signed in", async () => {
|
||||
mockAuth.mockResolvedValueOnce(null);
|
||||
await expect(beginTwoFactor()).rejects.toThrow("NEXT_REDIRECT: /login");
|
||||
expect(mockRedirect).toHaveBeenCalledWith("/login");
|
||||
});
|
||||
|
||||
it("generates secret, updates database, and revalidates path", async () => {
|
||||
await beginTwoFactor();
|
||||
expect(mockGenerateTotpSecret).toHaveBeenCalled();
|
||||
expect(mockEncrypt).toHaveBeenCalledWith("JBSWY3DPEHPK3PXP");
|
||||
expect(db.update).toHaveBeenCalledWith(User);
|
||||
expect(hoistedUpdateSet).toHaveBeenCalledWith(
|
||||
expect.objectContaining({
|
||||
twoFactorSecret: "encrypted-secret-payload",
|
||||
twoFactorConfirmedAt: null,
|
||||
twoFactorRecoveryCodes: expect.any(String),
|
||||
}),
|
||||
);
|
||||
expect(mockRevalidatePath).toHaveBeenCalledWith("/settings/2fa");
|
||||
});
|
||||
});
|
||||
|
||||
describe("confirmTwoFactor", () => {
|
||||
it("redirects on rate limit", async () => {
|
||||
mockRateLimit.mockResolvedValueOnce({ ok: false });
|
||||
await expect(
|
||||
confirmTwoFactor(fakeForm({ code: "123456" })),
|
||||
).rejects.toThrow("NEXT_REDIRECT: /settings/2fa?error=ratelimit");
|
||||
expect(mockRedirect).toHaveBeenCalledWith("/settings/2fa?error=ratelimit");
|
||||
});
|
||||
|
||||
it("redirects on invalid TOTP and recovery code", async () => {
|
||||
mockVerifyTotp.mockReturnValueOnce(false);
|
||||
await expect(
|
||||
confirmTwoFactor(fakeForm({ code: "INVALID" })),
|
||||
).rejects.toThrow("NEXT_REDIRECT: /settings/2fa?error=badcode");
|
||||
expect(mockRedirect).toHaveBeenCalledWith("/settings/2fa?error=badcode");
|
||||
});
|
||||
|
||||
it("confirms when TOTP code is valid", async () => {
|
||||
mockVerifyTotp.mockReturnValueOnce(true);
|
||||
await expect(
|
||||
confirmTwoFactor(fakeForm({ code: "123456" })),
|
||||
).rejects.toThrow("NEXT_REDIRECT: /settings/2fa?enabled=1");
|
||||
expect(hoistedUpdateSet).toHaveBeenCalledWith(
|
||||
expect.objectContaining({
|
||||
twoFactorConfirmedAt: expect.any(Date),
|
||||
}),
|
||||
);
|
||||
expect(mockRedirect).toHaveBeenCalledWith("/settings/2fa?enabled=1");
|
||||
});
|
||||
|
||||
it("confirms when recovery code is valid", async () => {
|
||||
mockVerifyTotp.mockReturnValueOnce(false);
|
||||
await expect(
|
||||
confirmTwoFactor(fakeForm({ code: "CODE-1234" })),
|
||||
).rejects.toThrow("NEXT_REDIRECT: /settings/2fa?enabled=1");
|
||||
expect(mockRedirect).toHaveBeenCalledWith("/settings/2fa?enabled=1");
|
||||
});
|
||||
});
|
||||
|
||||
describe("disableTwoFactor", () => {
|
||||
it("redirects on invalid code", async () => {
|
||||
mockVerifyTotp.mockReturnValueOnce(false);
|
||||
await expect(
|
||||
disableTwoFactor(fakeForm({ code: "INVALID" })),
|
||||
).rejects.toThrow("NEXT_REDIRECT: /settings/2fa?error=badcode");
|
||||
expect(mockRedirect).toHaveBeenCalledWith("/settings/2fa?error=badcode");
|
||||
});
|
||||
|
||||
it("clears two-factor secret and recovery codes on valid verification", async () => {
|
||||
mockVerifyTotp.mockReturnValueOnce(true);
|
||||
await expect(
|
||||
disableTwoFactor(fakeForm({ code: "123456" })),
|
||||
).rejects.toThrow("NEXT_REDIRECT: /settings/2fa?disabled=1");
|
||||
expect(hoistedUpdateSet).toHaveBeenCalledWith({
|
||||
twoFactorSecret: null,
|
||||
twoFactorRecoveryCodes: null,
|
||||
twoFactorConfirmedAt: null,
|
||||
});
|
||||
expect(mockRedirect).toHaveBeenCalledWith("/settings/2fa?disabled=1");
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user